Data Processing Addendum (DPA)
Last updated: August 1, 2026
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service and Privacy Policy between ExpenseDesk Pro (“ExpenseDesk,” “we,” “us”) and the customer (“Customer,” “you”) that uses the service (the “Service”). This DPA applies where and to the extent that ExpenseDesk processes personal data on the Customer’s behalf.
1. Introduction & Relationship to the Terms / Privacy
This DPA supplements and is incorporated into the Terms of Service and Privacy Policy, which apply in full and remain in effect. Its purpose is to reflect the parties’ agreement regarding the processing of personal data that the Customer enters about other people. This DPA applies only where ExpenseDesk processes personal data on the Customer’s behalf to provide the Service. For data about the Customer’s own account and users, ExpenseDesk acts as a controller under the Privacy Policy, and that processing is outside the scope of this DPA. In the event of a conflict concerning processing on the Customer’s behalf, this DPA prevails as set out in Section 14.
2. Definitions
“Controller” means the person or entity that determines the purposes and means of the processing of personal data.
“Processor” means the person or entity that processes personal data on the controller’s behalf.
“Personal data” means any information relating to an identified or identifiable natural person that is processed within the Service on the Customer’s behalf.
“Sub-processor” means any third party engaged by ExpenseDesk to process personal data on the Customer’s behalf.
“Data subject” means the natural person to whom the personal data relates.
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
“Applicable data protection law” means all data protection and privacy laws and regulations applicable to the processing under this DPA, including, where relevant, U.S. state privacy laws.
3. Roles & Scope
With respect to personal data processed under this DPA, the Customer is the controller and ExpenseDesk is the processor. Where the Customer is itself a processor for a third party, ExpenseDesk acts as a sub-processor.
Subject matter: the provision of the Service under the Terms.
Duration: for as long as the Customer uses the Service and until the return or deletion of data under Section 10.
Nature and purpose: the storage, hosting, processing, and display of the Customer’s data to operate the Service, generate the documents and reports the Customer requests, and perform the integrations the Customer authorizes.
Types of personal data: contact and identity details and, where the Customer chooses to enter them, sensitive identifiers such as the last four digits of a Social Security Number, bank or direct-deposit details, employer identification numbers (EIN), W-9 records and pay information, as well as the approximate GPS location captured by the mobile time clock.
Categories of data subjects:the Customer’s clients, employees, and subcontractors, and other individuals whose data the Customer chooses to enter into the Service.
4. Customer Instructions & Compliance
ExpenseDesk will process personal data only in accordance with the Customer’s documented instructions, unless otherwise required by law. The Terms, this DPA, and the Customer’s use of the Service (including its configuration and the features it enables) constitute the Customer’s complete documented instructions. If ExpenseDesk believes an instruction infringes applicable data protection law, it will notify the Customer. The Customer warrants that it has a lawful basis for the processing, that it has provided the required notices and obtained the required consents, and that its collection and use of the personal data comply with applicable law. The Customer is solely responsible for the accuracy, quality, and legality of the personal data and for deciding what information it enters, including sensitive data.
5. Confidentiality
ExpenseDesk will ensure that persons authorized to process the personal data are subject to appropriate duties of confidentiality (whether contractual or statutory) and have been informed of the confidential nature of the data. Access to personal data is limited to personnel who need such access to provide, maintain, or support the Service.
6. Security Measures
ExpenseDesk will implement commercially reasonable technical and organizational measures appropriate to the risk to protect personal data, including: encryption in transit (HTTPS); database access controls via row-level security (RLS) so that each account can access only its own businesses’ data; passwords stored only as a secure hash; optional multi-factor authentication; leaked-password protection; and server-side handling of integration tokens. No online service can guarantee absolute security. ExpenseDesk may update these measures provided it does not materially reduce the level of protection.
7. Sub-processors
The Customer generally authorizes ExpenseDesk to engage the sub-processors listed in the Privacy Policy, including Supabase (database, authentication, and file storage), Vercel (hosting), Stripe (subscription billing and, if enabled, payments), Intuit / QuickBooks Online (only if connected), Resend (transactional email), web push providers, and the product analytics provider. ExpenseDesk will impose on each sub-processor data-protection obligations substantially equivalent to those in this DPA and remains responsible for its sub-processors’ compliance. ExpenseDesk will give the Customer notice before adding or replacing a sub-processor (by updating the list or other reasonable notice), and the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may stop using or terminate the affected part of the Service.
8. Data-Subject Requests
Taking into account the nature of the processing, ExpenseDesk will assist the Customer, by appropriate technical and organizational measures and insofar as reasonably possible, in responding to requests from data subjects exercising their rights under applicable law. The Service’s self-service tools allow the Customer to access, export, correct, and delete personal data directly. If ExpenseDesk receives a data-subject request relating to data processed on the Customer’s behalf, it will refer the request to the Customer and will not respond directly unless legally required.
9. Personal-Data-Breach Notification
ExpenseDesk will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf. The notification will describe, to the extent reasonably known, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed to address it. ExpenseDesk will reasonably cooperate with the Customer and take reasonable steps to mitigate the breach. Notice of a breach is not an acknowledgment of fault or liability by ExpenseDesk.
10. Return & Deletion
During the term, the Customer may export its data at any time using the Service’s export tools. Upon termination or expiration, or when the Customer deletes a business or its account, the associated personal data will be removed from ExpenseDesk’s active systems. Residual copies may persist for a limited period in encrypted backups before being overwritten on the normal backup cycle. ExpenseDesk may retain personal data to the extent required by law, subject to applicable legal, tax, accounting, or security retention obligations, in which case this DPA will continue to apply to such retained data.
11. Audits & Information
ExpenseDesk will make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations of this DPA. Upon a reasonable written request, and subject to confidentiality obligations, ExpenseDesk will respond to reasonable inquiries about its security measures and processing. Any audit will be limited to no more than once per year (unless otherwise required by law or a regulatory authority), conducted on reasonable notice during normal business hours, will avoid interfering with ExpenseDesk’s operations, and will not provide access to other customers’ data or third-party confidential information.
12. International Transfers
ExpenseDesk stores and processes personal data on infrastructure located in the United States. The Service is intended for users in the United States. If the Customer enters personal data relating to data subjects located outside the United States, the Customer is responsible for ensuring it has a valid legal mechanism for that transfer and that processing in the United States complies with applicable law.
13. Liability
Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service, and any reference to a party’s liability in the Terms means that party’s aggregate liability under the Terms and this DPA taken together.
14. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service or Privacy Policy concerning the subject matter of processing personal data on the Customer’s behalf, this DPA will prevail. In all other respects, the Terms remain in full force. This DPA is offered in English and Spanish for the Customer’s convenience; in the event of any conflict or discrepancy between the versions, the English version governs.
15. Contact
Questions or requests regarding this DPA can be directed to access@expensedeskpro.com.